Bug 198745
Summary: | To block automatic download in sandboxed iframe | ||
---|---|---|---|
Product: | WebKit | Reporter: | yaoxia |
Component: | Frames | Assignee: | Nobody <webkit-unassigned> |
Status: | NEW | ||
Severity: | Normal | CC: | aestes, bfulgham, conrad_shultz, dbates, fred.wang, jberlin, webkit-bug-importer |
Priority: | P2 | Keywords: | InRadar |
Version: | WebKit Nightly Build | ||
Hardware: | All | ||
OS: | All |
yaoxia
Preventing automatic download in sandboxed iframe should be the default as downloads can bring security vulnerabilities to the system.
I'm hoping to see implementer interest.
whatwg/html discussion: https://github.com/whatwg/html/issues/3236
PR: https://github.com/whatwg/html/pull/4293
WPT (already checked in): https://github.com/web-platform-tests/wpt/commit/245334dcc1695c3dbc4e1fcdbe849224234093fc
Attachments | ||
---|---|---|
Add attachment proposed patch, testcase, etc. |
Radar WebKit Bug Importer
<rdar://problem/51614021>